Improper Authorization in Hospital Management System by onetwothreeneth
CVE-2026-105382
Key Information:
- Vendor
Onetwothreeneth
- Status
- Vendor
- CVE Published:
- 5 October 2026
Badges
What is CVE-2026-105382?
A vulnerability has been identified in the Hospital Management System by onetwothreeneth, specifically affecting the function update_subaccount in php/controller.php related to account administration. An issue with the user_id argument allows for improper authorization, enabling remote exploitation. Although reported, there has been no official response from the developers regarding this flaw. It is critical for users of affected versions to remain vigilant as the exploit details have been published.
Affected Version(s)
HospitalManagementSystem 9ef91ed6007314b6473110ed699dff76d158f61d
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
